Live data from Hacker News

Google Chrome Hacked?

vupen.com

61–70 of 223 posts

Re: Google Chrome Hacked?

#61
post #23

vupen: "Hey Google, your browser has a very nasty bug that allows for potentially horrible things to happen. We thought we'd share that with the world. If you'd like to know where it is though, you'd better give us money."

Why not? This is highly specialized research that not even well-paid Google employees were able to do. This is actually quite common in recent years for bug hunters and exploit developers. I can think of a dozen or so companies that do the same thing. Immunity is another example. Trying to use a moral argument to get out of compensating someone when you have the resources to do so is shameful. Sorry, but this stuff i…

Publicly announcing a security vulnerability, claiming that you're sharing it with other clients with the intent of using it for "weaponized ... offensive missions", and then demanding a fee to gain the information to protect against said weaponization, sounds an awful lot like extortion. In the offline world, I don't think you can legally run a business with a strategy of: discover a problem in the security at one of Exxon's plants, publicly announce that you've discovered a vulnerability and will be selling the information to third parties, and then demand $N from Exxon for the details.

Re: Google Chrome Hacked?

#62
post #41

I wonder if this is a sandboxing issue with NaCL, which is I noticed was added (default disabled) in Chrome 11. Considering how non specific VUPEN are, I wouldn't be surprised if they're hiding this.

Sounds like it's Windows only, so I'd expect it to be related to the Windows sandboxing.

Re: Google Chrome Hacked?

#63
post #31
post #24

Earlier quoted context omitted.

The reality is that there is probably no chance that they would ever find these bugs if they weren't funded to do it and the only way to be funded is to have customers. The net result is probably safer software for all.

The net result in this case is the government owning a zero-day root exploit for every Chrome/Win citizen’s computer. It’s worse than zero-day because we have no reason to expect a patch, so the window of attack will stay open.

Wouldn't "the government" keep quiet about even having found an exploit? Why let VUPEN publicize this if they intend to use it?

Re: Google Chrome Hacked?

#64
post #22

Unless Google is one of their customers it may actually be a little while before this exploit is fixed. VUPEN does security research and doesn't disclose to original vendors unless they happen to be customers. I both love and hate them. They are extremely talented and find absolutely awesome bugs that are hard to discover without a lot of work, and I hate them because they don't disclose their work unless it is for m…

Funny thing is Google does actually pay for reported security bugs. Up to $3133.70: http://dev.chromium.org/Home/chromium-security/vulnerability...

Re: Google Chrome Hacked?

#65
post #49
post #24

Earlier quoted context omitted.

The reality is that there is probably no chance that they would ever find these bugs if they weren't funded to do it and the only way to be funded is to have customers. The net result is probably safer software for all.

I'm confused. Why would the government want to break Chrome? Also, if they are not going to release the exploit soon (especially to Google), why are you saying 'safer software for all'?

you know that there is more than one government on earth... and all of them arent pro free-speech :)

Safer software for all, because it's a better thing that VUPEN discover the bug than if it's discovered by some criminals who keep it secret and scam/hack

Re: Google Chrome Hacked?

#66
post #49
post #24

Earlier quoted context omitted.

The reality is that there is probably no chance that they would ever find these bugs if they weren't funded to do it and the only way to be funded is to have customers. The net result is probably safer software for all.

I'm confused. Why would the government want to break Chrome? Also, if they are not going to release the exploit soon (especially to Google), why are you saying 'safer software for all'?

"Why would the government want to break Chrome?" So they could run arbitrary payloads targeted at specific people.

Re: Google Chrome Hacked?

#67
post #2

"This code and the technical details of the underlying vulnerabilities will not be publicly disclosed. They are shared exclusively with our Government customers" Love the capital G.

It's a standard formation in some publications--e.g., the New York Times.

Re: Google Chrome Hacked?

#68
"it works on all Windows systems (32-bit and x64)"

They didn't say that the exploit didn't work on Mac or Linux, but one can only assume they tested those and weren't successful?

Re: Google Chrome Hacked?

#69
post #22

Unless Google is one of their customers it may actually be a little while before this exploit is fixed. VUPEN does security research and doesn't disclose to original vendors unless they happen to be customers. I both love and hate them. They are extremely talented and find absolutely awesome bugs that are hard to discover without a lot of work, and I hate them because they don't disclose their work unless it is for m…

Looking at VUPEN services it sounds like HBGary twin : http://www.vupen.com/english/services/ "offensive security", yep. The guys are dirty like the Gary. Why a racket and government always means a happy marriage?

VUPEN know what they're doing. That's the difference.

They're an actual security company.

Re: Google Chrome Hacked?

#70
post #60

Earlier quoted context omitted.

"Whore" is vernacular, but that doesn't mean the FBI uses the word when they announce they've cracked a prostitution ring.

Only hiring offensive security vendors who won't use the term 'pwned' is roughly equivalent to trying to purchase a hand job from someone who won't use the term 'whore'. Neither is likely to get you very far.

I'd imagine the high-ends of both professions have higher standards of class and behaviour than the lower-ends.
Post reply on HN